Query the httpBreakdownMetrics dataset
List the client IP addresses with the most blocked requests from the httpBreakdownMetrics dataset, with curl or the GraphiQL playground.
You can list the client IP addresses with the most blocked requests with the GraphQL API, from curl or the GraphiQL playground.
The httpBreakdownMetrics dataset of Real-Time Metrics splits the requests to your applications by values such as remoteAddress, the IP address of the client, geolocCountryName, and requestPath. For each combination of values, it counts requests, blockedRequests, and wafThreatRequests. For every field and filter of the dataset, refer to Real-Time Metrics GraphQL fields.
The dataset returns hour buckets, even for a range of one hour. For how the range sets the bucket size, refer to How Real-Time Metrics works. Real-Time Metrics keeps the data of httpBreakdownMetrics for 90 days. For the retention of every dataset, refer to Real-Time Metrics limits.
Prerequisites
- A personal token, for
curl. To create one, refer to How to manage a personal token. curl, or the GraphiQL playground. The playground needs a browser session signed in to your Azion account, or it returns an error. To open it, refer to GraphiQL Playground.
List the addresses with the most blocked requests
This query adds up blockedRequests for each remoteAddress over one hour, and returns the 20 addresses with the highest totals:
Each argument shapes the result:
aggregate: { sum: blockedRequests }totals the blocked requests that pass the filter. The aliastotalBlocked: sumrenames that total in the response.groupBy: [remoteAddress]returns one total per client IP address.orderBy: [sum_DESC]lists the highest total first.[sum_ASC]lists the lowest first.limit: 20caps the response at 20 rows. For the maximum, refer to Real-Time Metrics limits.filterkeeps only the data that matches its conditions. Here, the conditions set the time range.tsGtesets the start of the range, which the result includes.tsLtsets the end, which the result excludes.
Both dates take the YYYY-MM-DDTHH:mm:ss format. Replace the dates in the example with the hour you want to read. tsGte and tsLt are an alternative to tsRange, the range filter of the Real-Time Metrics quickstart.
To run the query with curl, send a POST request to https://api.azion.com/v4/metrics/graphql. Replace [TOKEN VALUE] with your personal token:
The API answers 200 with one row per address:
Each row pairs an address with its total of blocked requests, highest first, up to 20 rows. An address with no blocked request reads 0 in totalBlocked.
An empty httpBreakdownMetrics array means no request matched: check that the range falls inside the 90 days of retention. A request without the Authorization header returns 401.
To run the query in the GraphiQL playground instead, paste the query from the first block.